MD-102 Prepare infrastructure for devices Practice Question
You are the Intune administrator for Fabrikam, Inc., which has 5,000 Windows 10 devices. The company wants to move from on-premises Group Policy management to Intune. You have already deployed the Intune Management Extension to all devices. However, some devices are not receiving policies. You discover that these devices are not enrolled in Intune. You need to enroll all devices as quickly as possible with minimal user interaction. The devices are already joined to on-premises Active Directory. You have Microsoft Entra ID Connect configured. What should you do?
⚠ Common exam trap
It's easy for candidates to confuse the Enrollment Status Page (ESP) as an enrollment trigger, when in fact it is a post-enrollment configuration tool, or they mistakenly believe Autopilot is required for hybrid devices, ignoring the simpler automatic enrollment path via MDM scope and hybrid join.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the MDM user scope in Microsoft Entra ID to All, and ensure devices are hybrid joined.
Configuring the MDM user scope to 'All' in Microsoft Entra ID triggers automatic MDM enrollment for hybrid Azure AD-joined devices when combined with Microsoft Entra ID Connect. Since the devices are already joined to on-premises AD and Entra ID Connect is configured, setting the MDM scope to 'All' enables automatic, silent enrollment via the scheduled task created by the Group Policy for automatic enrollment, requiring no user interaction beyond sign-in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the MDM user scope in Microsoft Entra ID to All, and ensure devices are hybrid joined.
Why this is correct
This enables automatic enrollment for hybrid joined devices.
- ✗
Distribute a script to each user to run manually.
Why it's wrong here
Manual execution is not efficient.
- ✗
Deploy Windows Autopilot to reset and re-enroll each device.
Why it's wrong here
Autopilot is for new or reset devices, not for existing ones.
- ✗
Use the Intune Enrollment Status Page to force enrollment.
Why it's wrong here
ESP is for new devices, not existing ones.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
MDM
MDM stands for Mobile Device Management, a technology that allows IT administrators to securely manage, monitor, and enforce policies on mobile devices like smartphones and tablets from a central console.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.